
Der gefälschte „One Battle After Another“-Torrent versteckt bösartige PowerShell-Malware-Loader in Untertiteldateien, die letztendlich Geräte mit der Agent Tesla RAT-Malware infizieren.
https://www.bleepingcomputer.com/news/security/fake-one-battle-after-another-torrent-hides-malware-in-subtitles/

16 Kommentare
Id wager most malicious movie torrents were made with funding from hollywood.
Well…
If you download something like this, you deserve what’s coming.
„The downloaded One Battle After Another movie torrent used in the attacks contains various files, including a movie file (One Battle After Another.m2ts), two image files (Photo.jpg, Cover.jpg), a subtitles file (Part2.subtitles.srt), and a shortcut file (CD.lnk) that appears as a movie launcher.“
When the CD shortcut is executed, it launches Windows commands that extract and run a malicious PowerShell script embedded in the subtitle file between lines 100 and 103
The extracted PowerShell scripts act as a malware dropper, performing the following actions on the host:
* **Stage 1** – Extracts the One Battle After Another.m2ts file as an archive using any available extractor.
* **Stage 2** – Creates a hidden scheduled task (RealtekDiagnostics) that runs RealtekCodec.bat
* **Stage 3** – Decodes embedded binary data from Photo.jpg and writes restored files to the Windows Sound Diagnostics Cache directory.
* **Stage 4** – Ensures %LOCALAPPDATA%\Packages\Microsoft.WindowsSoundDiagnostics\Cache exists.
* **Stage 5** – Extracts Cover.jpg contents into the Cache directory, including batch files and PowerShell scripts.
The files extracted in the final stage are used to check whether Windows Defender is active, install Go, extract the final payload (AgentTesla), and load it directly into memory.
AgentTesla is a long-running (since 2014) Windows RAT and information stealer, commonly used to steal browser, email, FTP, and VPN credentials, as well as to capture screenshots.
While Agent Tesla is not new, it remains widely used due to its reliability and ease of deployment.
Bitdefender has noted that in other movie titles, for example, ‚Mission: Impossible – The Final Reckoning,‘ it has observed other families used, such as Lumma Stealer.
Torrent files from anonymous publishers often contain malware, so it is recommended that users avoid pirating new movies entirely for safety.
Very sneaky, the torrent includes real subtitle files with extra lines in different places, and a CD.lnk file that supposedly „launches“ the movie when you run it, but instead it’s a script that extracts those extra lines from the subtitle files, puts them together to create a bigger file, and that is the real McCoy.
This is nothing, you have to execute a file that isn’t the media but instead a CD.lnk.
It’s a run of the mill trojan that requires user interaction. And it only works on windows…
Just don’t use windows…
I only use torrents for downloading Linux isos
If I ever downloaded torrents of movies I would probably examine the contents of the folder I’m downloading and only select the necessary files. Most of them (I’ve heard) come with a bunch of junk extra files. In that hypothetical scenario it’s possible I could have been downloading movies and music for years without ever getting a virus
Maybe get off your ass and go support cinemas.
edit: lol. downvotes are telling.
I highly recommend for anyone that uses Radarr or Sonarr to always have certain extensions of file blocked automatically from download with torrent clients.
Everyone should get on Usenet for much cleaner piracy.
Reminder for everyone that could fall victim to this to go into their Torrent application right now and navigate to:
*Settings > Downloads > Excluded Filenames*
And paste this (review this yourself in case you utilize any of these btw)
„„
*.ade
*.adp
*.apk
*.app
*.bas
*.bat
*.bin
*.chm
*.cmd
*.com
*.cpl
*.crt
*.dll
*.drv
*.exe
*.hlp
*.hta
*.html
*.inf
*.ins
*.ipa
*.iso
*.isp
*.jar
*.js
*.jse
*.key
*.lnk
*.mda
*.mdb
*.mdt
*.mdw
*.mdz
*.mht
*.mhtml
*.msi
*.msp
*.nsh
*.ocx
*.php
*.pif
*.potm
*.potx
*.ppam
*.ppsx
*.pptm
*.ps1
*.ps2
*.psd1
*.psm1
*.py
*.reg
*.scf
*.scr
*.sh
*.sldm
*.sldx
*.sys
*.tmp
*.torrent
*.vb
*.vbe
*.vbs
*.vxd
*.wsf
*.wsh
*.xlam
*.xlsb
*.xlsm
*.xltm
*.zipx
*sample.avi
*sample.mkv
*sample.mp4
This is why I don’t pirate anything. It’s not worth the risk.
Linkin_Park_Numb.exe rides again!
So how does it get executed?
Or does it rely on user stupidity?
Still better than the cam release I got with people walking in front of the projector and a russian dub with the same guy doing all the charscters.
Glad I use Usenet where no one would even bother lol